Microsoft Copilot vulnerability leads to Surface firmware bricking
Story essentials
Microsoft, Jack Darcy (Security Researcher)
Global
March 2026
This page is produced by collecting and structuring multiple public reports. Sections based only on reporting or testimony affect the displayed assessment, and the page is updated when new information is identified.
About this article
COMPAMIR Editorial Team
The COMPAMIR editorial team brings together public reporting and links to the original coverage. We update the page as new information emerges.
Read our editorial policy- Earlier version 16/12/2026, 5:00:13 PM
Microsoft Copilot inadvertently triggered destructive firmware writes on Surface devices. The vulnerability allowed arbitrary writes to the embedded controller (SAM) when Secure Boot is disabled. Microsoft has committed to patching the issue and advises users to keep security features enabled.
Read next
Prioritized by shared people, places, and events.
Microsoft Releases Record-Breaking Security Patch Batch for September 2026
Microsoft released updates for 974 security vulnerabilities, the largest single patch batch in its history. The update includes two actively exploited zero-day flaws (CVE-2026-81963 and CVE-2026-85880). 113 vulnerabilities are rated as critical, including a DNS weakness and a Windows Shell remote code execution flaw. Security experts highlight the growing challenge for organizations to test and deploy such high volumes of patches.